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October 15, 2009 


FROM: Chief of Detectives 


TO: 


All Commanding Officers 



SUBJECT: SEARCH WARRANTS REQUESTING THE ANALYSIS OF DIGTTA1 
EVIDENCE 


The purpose of this Notice is to ensure that all Department personnel are advised of new 
procedures and guidelines for writing search warrants requesting the analysis of digital evidence 
(computer forensics). The analysis of digital evidence includes, but is not limited to- 
computers, cellular phones, hard drives, floppy disks, thumb drives, memory cards mp3 players 
or any other item capable of storing digital data. ’ F y ’ 

A recent Ninth Circuit Court of Appeals decision addressed these particular search warrants and 
will require specific language changes and additions. Due to this decision, failure to follow 
these new procedures and guidelines may result in violations of th P Fm.rth Amendment as 

well as the possibility of the digital evidence being suppressed in court. * " ’ 

Effective immediately - The following guidelines and procedures shall be followed when 
preparing search warrant affidavits which include the analysis of digital evidence. The following 
are guidelines only and are not meant to promote the use of “canned language ” in the c 

preparation of search warrants. All requests for digital analysis shall be supported by probable 
cause within the affidavit. F 

When preparing a search warrant affidavit for digital evidence, it must first be determined 
whether the digital evidence container (computer, cell phone, hard drive, etc.) itself must be 
seized, or searched onsite. If the container itself was instrumental to the crime, as in the vast 
majority of cases, then the entire container should be seized as evidence. In other words if the 
computer (or other digital container) was used in furtherance of the crime, such as downloading 
or distnbuting child pornography, storing stolen credit cards, or any other crime committed on 
the container itself, the container must be seized as evidence. 

If the computer only contains data being sought by the affiant, an onsite examination must be 
considered. This usually occurs when the data being sought is on a third party’s computer or 
network. Affiants should consider methods of obtaining the data they seek by other means than 
digital analysis (such as requesting the information from the third party). If this is not possible or 
the third party fails to comply, the affiant shall describe efforts to obtain the information in their 
affidavit. Affiants shall not take down third party computers or networks without first 
consulting Commercial Crimes Division’s (CCD), Computer Crimes Unit (CCU) 
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When the container to be seized or searched contains data which may contain privileged 
information (such as attomey/client information or medical records), the affiant shall request in 
the affidavit that a court appointed “Special Master” accompany the affiant on the search warrant 
service. This shall be done whether or not the attorney, physician, or other privileged possessor 
of data is a suspect in the crime being investigated. The Special Master will determine whether 
the containers may be seized or searched onsite. 

When requesting any digital analysis, the affiant shall be specific as to what information is to be 
sought. This may include, but is not limited to, names, user names, emails, keywords, Internet 
Protocol (EP) addresses, computer dates and times, computer ownership, or specific programs or 
photographs. Any data requested must be supported in the Statement of Probable Cause. The 
Department digital forensic examiner will only search for data specifically asked for and 
supported in the search warrant affidavit. No other information will be given to the affiant or 
investigating officer. Additionally, investigating officers will not be able to view any data on the 
container other than the data segregated by the forensic examiner pursuant to the search warrant. 

If the affiant has reason to believe that the suspect may be trying to hide or “disguise” digital 
evidence, the affiant may request that the forensic examiner search for such evidence, providing 
that the affiant has requested this in the search warrant affidavit and that the request is supported 
by probable cause. 

The affiant or any other investigating officer shall not turn on, search, or in any way view the 
information in the container, even if the computer or cellular phone is turned on at the time of the 
search warrant service. Instead, the affiant shall photograph the computer (or cell phone, etc.) 
and then unplug the device and/or remove the battery. The date and time of this procedure shall 
be written in the investigator’s notes. 

Due to the possibility of damage or changes to the original data container, the affiant shall 
request in the search warrant that the CCU make a duplicate “image” of the container and further 
request that the entire image be maintained by the CCU for court purposes. 

The new Ninth Circuit Court of Appeals decision gives magistrates the option of requesting that 
the Department waive the plain view rule for digital evidence. Affiants shall not agree to waive 
plain view. This may result in the judge’s refusal to sign the search warrant, however the 
Department will not agree to a waiver of the plain view rule in any case. This should not be an 
issue as magistrates do not appear to be requesting this waiver. 

These new procedures will assist the Department in complying with the Ninth Circuit Court of 
Appeals decision. Failure to comply with these procedures may result in either a rejection of the 
affiant’s digital analysis request, or a request for an additional “piggy back” warrant which fully 
complies with the above procedures. 
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? Y p U haVC any / aSUes 0r ^ uestlons regarding these new procedures, please feel free to contact 
the Commercial Cnmes Division, Computer Crimes Unit, at (213) 533-4657. Off hours please 
contact Real-Time Analysis & Critical Response Division, at (213) 484-6700. 



DISTRIBUTION “B” 








